LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-4249

wso2 · api control plane

Published
CVSS8.6
Severityhigh
WeaknessCWE-707
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Description

The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful exploitation of this vulnerability can disrupt the API Gateway, preventing legitimate API traffic from being processed and impacting complete service availability. The denial of service is persistent, requiring manual intervention to restore normal operations.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-4249

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-4249.